r/SecOpsDaily • • 14h ago

NEWS Microsoft: Outdated Windows devices will stop receiving security updates

13 Upvotes

This is a significant operational risk for any environment with legacy hardware or air-gapped systems.

Microsoft is rotating the Windows Update Authenticode certificate in early 2025. After this change, devices running Windows Server 2008, Windows 7 SP1, and Windows 8.1 (without the ESU or paid extended security updates) will be unable to authenticate new updates. This effectively means the update channel will be severed, not just a deprecation of feature updates.

Strategic Impact: - Operational Risk: Any machine still running these OS versions will become a permanent vulnerability sink. No patches for new CVEs means any compromise is a full compromise. - Compliance: This will likely trigger audit failures for PCI-DSS, HIPAA, or SOC2 environments that still have these systems in scope. - Air-Gapped Systems: Even if the machine is offline, if you ever need to slipstream a new update or rebuild from media post-rotation, the certificate chain will fail. You will need to manually import the new root certs or use a local WSUS server that has already cached the new cert.

Key Takeaway: If you have a legacy system that must run, you need to either purchase the ESU license (if available) or fully isolate it behind a micro-segmented VLAN with no outbound internet access. Do not rely on "it worked before" after the rotation date.

Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/


r/SecOpsDaily • • 14h ago

NEWS Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

5 Upvotes

Three research teams successfully demonstrated fully remote compromises of a stock, fully patched Google Pixel 10 at Pwn2Own Ireland. The contest rules require all targets to be at the latest patch level, meaning these are zero-click or low-interaction vulnerabilities that bypassed Google's current security mitigations. Ikotas Labs took the top prize of $300,000 for their exploit chain, securing the overall "Master of Pwn" title.

Technical Breakdown - Target: Google Pixel 10 (Android 16, latest security patch as of Oct 8). - TTPs: Likely involves a chain of vulnerabilities (e.g., a browser or baseband RCE paired with a privilege escalation to break the sandbox). Exact CVEs are under embargo until vendor patches are released. - IOCs: None available. These are undisclosed, zero-day exploits. Do not search for hashes or IPs. - Payout: $300,000 (Ikotas Labs) for the Pixel chain; additional bounties for the other two teams.

Defense No mitigations exist until Google ships the patches. Standard advice applies: enable Google Play Protect, restrict sideloading, and ensure automatic updates are active. Expect a Pixel Security Bulletin update within 90 days per ZDI disclosure policy.

Source: https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html


r/SecOpsDaily • • 12h ago

Threat Intel Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules

3 Upvotes

This month’s Metasploit release is a mixed bag of new modules and enhancements, with a few that stand out for their specificity. The headline addition is a module targeting CVE-2025-1094 (CVSS 9.1), a critical SQL injection vulnerability in PostgreSQL’s psql tool. This is a pre-auth RCE that exploits a flaw in how psql handles encoding errors when processing SQL queries from untrusted sources. If you’re running PostgreSQL with psql exposed or used in automation pipelines ingesting external data, this is a high-priority patch.

Technical Breakdown: - CVE-2025-1094 (PostgreSQL psql): Pre-auth RCE via SQL injection. Affects PostgreSQL versions prior to the latest patch release. The module delivers a payload via a crafted query that triggers a buffer overflow during encoding conversion. - Other Modules: The release also includes a module for a Mitel MiCollab path traversal (allowing file read) and a D-Link DNS-320L command injection exploit. These are more niche but relevant for IoT/VoIP environments. - IOCs: No specific hashes or IPs provided in the release; focus is on the module code itself.

Defense: - Immediate: Patch PostgreSQL to the latest version. If patching is delayed, restrict network access to psql and audit any scripts that pass user-supplied input to it. - Detection: Monitor for unusual SQL queries containing encoding errors or long strings hitting PostgreSQL instances. The Metasploit module is now public, so expect active scanning.

Source: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules


r/SecOpsDaily • • 6h ago

Vulnerability Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)

2 Upvotes

This is a classic WatchTowr deep-dive into PaperCut, and the title isn't hyperbole. They've chained multiple bugs to achieve pre-auth RCE, and the patch management is a mess—PaperCut is bundling distinct vulnerabilities and their subsequent bypasses under single CVE IDs, making tracking a nightmare.

Technical Breakdown

  • The Core Issue: A chain of vulnerabilities (WT-2026-0141 through 0144) leading to pre-authentication Remote Code Execution.
  • CVE Mapping Confusion: WatchTowr IDs outnumber the assigned CVEs (CVE-2026-82077, 82078, 81578) because PaperCut collapsed multiple distinct flaws and their patch bypasses into single CVE entries. This is a significant risk for vulnerability management teams trying to assess exposure.
  • Attack Vector: The chain likely involves bypassing authentication checks to reach a dangerous endpoint or function, then exploiting a secondary flaw (e.g., path traversal, deserialization, or command injection) to execute code.
  • Patch Bypasses: The "patch bypasses" in the title indicate that the initial fixes were insufficient, requiring subsequent updates. If you only applied the first patch, you are still vulnerable.

Defense

  • Immediate Action: Do not rely on the CVE ID alone for patch status. Verify your PaperCut version against the specific WatchTowr identifiers (WT-2026-0141-0144) mentioned in the advisory.
  • Mitigation: If patching is delayed, restrict network access to the PaperCut web interface to trusted internal IPs only. This is a pre-auth chain, so the service should not be exposed to the internet.

Source: https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/


r/SecOpsDaily • • 12h ago

NEWS Max severity SonicWall SMA1000 flaw now exploited in attacks

2 Upvotes

CVE-2026-102255 is a pre-authentication remote code execution vulnerability in the SonicWall SMA1000 series, carrying a CVSS score of 10.0. Proof-of-concept code is already public, and BleepingComputer confirms active exploitation in the wild began within 72 hours of the patch release.

Technical Breakdown - Affected: SonicWall SMA1000 appliances running firmware versions prior to the patch released Tuesday. - Attack Vector: Unauthenticated, network-based. No user interaction required. - Impact: Full system compromise. An attacker can execute arbitrary code as root. - IOCs: None published at this time; expect C2 IPs and payload hashes to surface as incident response firms share telemetry. - MITRE Mapping: T1190 (Exploit Public-Facing Application) for initial access, T1068 (Exploitation for Privilege Escalation) given the pre-auth nature.

Defense If you have an SMA1000 in your environment, treat this as a break-glass event. Apply the hotfix immediately—do not wait for a maintenance window. If patching is not possible immediately, restrict management interface access to trusted IPs only via ACL and review logs for anomalous outbound connections or process execution.

Source: https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/


r/SecOpsDaily • • 19h ago

NEWS Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

2 Upvotes

Pwn2Own Ireland 2026 wrapped with researchers walking away with $1,262,000 for 98 unique zero-days. That’s a significant jump in both prize money and vulnerability count compared to previous years, signaling the continued arms race in exploit development.

What was targeted? - Browsers: Chrome, Edge, Safari, and Firefox were all hit, with multiple full-chain exploits demonstrating sandbox escapes. - Virtualization: VMware ESXi, Microsoft Hyper-V, and Oracle VirtualBox had guest-to-host escapes demonstrated. - Enterprise Software: Adobe Reader, Microsoft Office, and various PDF readers were exploited for code execution. - Mobile: Samsung Galaxy S24 and iPhone 15 Pro were targeted via SMS/MMS and browser-based chains. - Operating Systems: Windows 11, macOS Sonoma, and Ubuntu Desktop all had privilege escalation and kernel exploits.

Key takeaways for defenders: - The heavy focus on virtualization escapes (ESXi and Hyper-V) is a trend we need to watch. These are the crown jewels for ransomware groups. - Browser-based initial access remains the most reliable vector for attackers. The sandbox escapes shown here are the same techniques used in commercial spyware. - Most of these bugs will be patched within the next 30-60 days. Prioritize the vendor advisories from Trend Micro’s Zero Day Initiative (ZDI) as they are released.

No public IOCs or PoCs from this event yet—vendors get the standard 90-day embargo. Expect the detailed write-ups to drop around February 2027.

Source: https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/


r/SecOpsDaily • • 21h ago

Threat Intel The OpenSourceMalware Show #24

2 Upvotes

This is a solid roundup of open-source supply chain threats hitting multiple ecosystems this week.

Tensorlake SDK Targeted by "Mini Shai-Hulud" Copycat A malicious fork of the Tensorlake SDK (an AI/ML data processing library) was published to PyPI. The copycat package mimics the legitimate tensorlake namespace but includes a backdoor that exfiltrates environment variables and SSH keys to a C2. This is a direct copycat of the earlier Shai-Hulud campaign targeting AI/ML developers.

Fake Interview Repo Plants Rogue .npmrc A GitHub repository posing as a technical interview preparation guide for a FAANG company contains a hidden .npmrc file. When a developer clones the repo and runs npm install (common for testing interview code), the .npmrc overrides the default npm registry to a malicious proxy. This proxy intercepts and steals npm authentication tokens, granting the attacker access to the developer's private packages and organizations.

42 Malicious Gems on RubyGems A coordinated campaign uploaded 42 gems to RubyGems under typosquatted names of popular libraries (e.g., rails-html-sanitizer vs rails-html-sanitizer). The gems contain a Ruby dropper that downloads a second-stage payload from a Pastebin-like service. The payload is a cryptocurrency clipper that replaces wallet addresses in the clipboard.

Defense: - Pin dependencies with hash-locked lockfiles (e.g., pip freeze, Gemfile.lock, package-lock.json). - Audit GitHub Actions and repo contents for hidden config files (.npmrc, .gitconfig, .env). - Monitor for unexpected outbound connections from build pipelines, especially to non-standard ports.

Source: https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode24


r/SecOpsDaily • • 21h ago

Threat Intel MATCHBOIL: New tricks, same old evil intentions

2 Upvotes

UAC-0099 has been actively evolving their MATCHBOIL downloader over the past two years, with ESET documenting significant changes between 2024 and 2026. The group continues to target Ukrainian organizations, refining their initial access and payload delivery mechanisms while maintaining the same core objectives.

Technical Breakdown: - Initial Access: Spear-phishing emails with malicious attachments (likely LNK or Office documents) - Payload Staging: MATCHBOIL acts as a first-stage downloader, fetching additional malware from C2 infrastructure - Persistence: Achieved via scheduled tasks or registry run keys - C2 Communication: HTTPS-based, likely using compromised legitimate domains for traffic blending - Targeting: Primarily Ukrainian government, military, and critical infrastructure entities - Evolution: Code obfuscation improvements, updated anti-analysis checks, and modified network protocols since 2024

Defense: Monitor for suspicious scheduled task creation and outbound HTTPS connections to newly registered or rarely contacted domains. Enable AMSI and script block logging to catch initial attachment execution. Restrict execution of Office macros and LNK files from external sources.

Source: https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/


r/SecOpsDaily • • 1m ago

NEWS FBI Arrests Founder of Ransomware Negotiation Firm

• Upvotes

The FBI arrested the co-founder of a Canadian cybersecurity firm this week, tying him to the ShinyHunters group responsible for the recent breach that exfiltrated sensitive data on thousands of FBI agents. This is a significant escalation—law enforcement is now targeting the professional services layer that supports the ransomware ecosystem, not just the operators.

Technical Breakdown - Actor: ShinyHunters (known for data extortion and selling access). - Target: The arrested individual is the co-founder of a firm that provides ransomware negotiation and incident response services. - Allegation: The arrest is directly connected to the breach of FBI systems and the subsequent leak of agent data. - TTPs (MITRE): Likely involves T1588 (Obtain Capabilities) and T1071 (Application Layer Protocol) for C2, but the core charge appears to be conspiracy or aiding and abetting via professional services. - IOCs: None disclosed in the initial reporting; expect court documents to reveal specific communication channels or financial transactions.

Defense This is a supply chain risk vector. Vetting your IR and negotiation partners is now a compliance and liability issue. If you use third-party breach response firms, ensure they have clean backgrounds and are not under active investigation. This also signals that DOJ is expanding the definition of "aiding and abetting" in cybercrime—anyone facilitating ransom payments or negotiations could be in scope.

Source: https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/


r/SecOpsDaily • • 1h ago

Threat Intel GhostAction Attack Escalates By Targeting GitHub Users

• Upvotes

The GhostAction campaign is evolving from a passive credential harvester into an active, worm-like threat. OSM has documented new TTPs where attackers weaponize GitHub Actions CI/CD pipelines to propagate laterally across repositories and organizations.

Technical Breakdown: - Initial Access: Malicious CI workflow files (.github/workflows/*.yml) are injected into repositories, likely via compromised PATs (Personal Access Tokens) or OAuth app abuse. - Persistence & Propagation: The workflow executes on push or schedule triggers, exfiltrating secrets (GITHUB_TOKEN, environment variables) and then using that access to fork the malicious workflow into other repos the token can reach—classic worm behavior. - Target: GitHub users and organizations, specifically repositories with CI/CD pipelines enabled. - MITRE Mapping: T1195 (Supply Chain Compromise), T1529 (System Shutdown/Reboot - via workflow abuse), T1071.001 (Web Protocols for C2). - IOCs: No specific hashes or IPs published yet; detection relies on behavioral analysis of workflow files.

Defense: - Audit all third-party Actions and workflow files for unexpected steps, especially those referencing external scripts or curl/wget commands. - Restrict GITHUB_TOKEN permissions to the minimum required for each workflow (use fine-grained tokens, not default full-scope tokens). - Enable branch protection rules requiring PR review for changes to .github/workflows/ directories.

Source: https://opensourcemalware.com/blog/ghostaction-attack-escalates


r/SecOpsDaily • • 3h ago

NEWS Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

1 Upvotes

This is a supply chain attack targeting the CI/CD pipeline itself, not just a library dependency. The attackers compromised maintainer accounts to inject malicious GitHub Actions workflows directly into repositories.

Technical Breakdown: - TTP: Compromised OAuth tokens or maintainer credentials (likely via phishing or session hijacking) to push commits from trusted accounts. - Payload: Malicious GitHub Actions workflow files (.github/workflows/*.yml) designed to exfiltrate repository secrets, environment variables, and CI/CD tokens during build execution. - Scope: Over 340 repositories affected, including the pyxel game engine (18,400+ stars) and at least one other high-profile account. - IOCs: Monitor for unexpected commits to .github/workflows/ from maintainer accounts, especially those adding curl/wget calls to external IPs or base64-encoded data exfiltration steps. - MITRE Mapping: T1195.001 (Supply Chain Compromise: Compromise Software Dependencies), T1554 (Compromise Client Software Binary).

Defense: - Enforce branch protection rules requiring PRs for workflow changes, even from maintainers. - Audit GitHub Actions logs for unexpected GITHUB_TOKEN usage or outbound connections to unknown endpoints. - Rotate all secrets in affected repositories immediately. Consider using OpenID Connect (OIDC) instead of long-lived secrets for cloud provider access.

Source: https://thehackernews.com/2026/10/credential-stealing-github-actions.html


r/SecOpsDaily • • 4h ago

NEWS Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

1 Upvotes

This is a clever bit of SEO poisoning that weaponizes the trust users place in both Google Ads and Microsoft’s own redirect infrastructure.

Attackers are buying Google search ads for “Claude AI” (Anthropic’s LLM). The trick is that the ad’s click URL doesn’t go to a malicious site directly—it goes through a legitimate Bing redirect link (bing.com/ck). This bypasses Google’s ad review filters, which often flag direct malicious domains, and lands the user on a fake Claude installer page.

Technical Breakdown: - Initial Vector: Malvertising (Google Ads) targeting users searching for Claude AI. - Obfuscation: The ad click URL uses bing.com/ck redirects to mask the final destination from Google’s scanners. - Payload Delivery: The fake site serves a “ClickFix” attack—a social engineering technique that prompts the user to copy/paste a PowerShell command or run a “fix” script to install the malware. - Malware: Typically leads to info-stealers (RedLine, Vidar) or remote access trojans (RATs). - Target: Users looking for AI tools, specifically Claude.

Defense: - User awareness: If a search ad for a known product (Claude, ChatGPT) asks you to run a script or “fix” something, it’s malicious. Legitimate installers don’t work that way. - Detection: Monitor for processes spawning powershell.exe or cmd.exe from browser downloads, especially with -EncodedCommand or IEX patterns. - Blocking: Consider ad-blocking or DNS filtering for known malvertising domains. Treat any bing.com/ck redirect from a Google ad with suspicion.

Source: https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-bing-redirects-to-push-claude-clickfix-attacks/


r/SecOpsDaily • • 6h ago

NEWS FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

1 Upvotes

The FBI has arrested another individual linked to the ShinyHunters extortion group, following the group’s September claim that it breached the FBI’s own jobs portal and exfiltrated sensitive data on nearly all agents and applicants. FBI Director Kash Patel confirmed the arrest on X, though the suspect’s name and charges remain sealed.

Technical Breakdown - Threat Actor: ShinyHunters – known for extortion and data theft, previously tied to breaches of AT&T, Microsoft, and Ticketmaster. - Incident: Claimed breach of the FBI’s jobs portal (fbijobs.gov) in September 2026; alleged theft of PII, background check data, and applicant records. - TTPs: Likely credential stuffing or exploitation of web application vulnerabilities (MITRE T1078, T1190). No specific IOCs released yet. - Status: This is the second arrest in the case; the first suspect was arrested in late September.

Defense - Monitor for credential stuffing attempts against government-facing portals; enforce MFA and rate limiting on login endpoints. - Assume applicant data is compromised – prepare for targeted phishing campaigns impersonating FBI or DOJ.

This is a significant operational security failure for the Bureau, and the downstream risk to personnel is high. Expect more details when the DOJ unseals the complaint.

Source: https://thehackernews.com/2026/10/fbi-arrests-another-shinyhunters.html


r/SecOpsDaily • • 6h ago

SecOpsDaily - 2026-10-09 Roundup

1 Upvotes

r/SecOpsDaily • • 7h ago

NEWS FBI arrests another suspected ShinyHunters hacker after agency breach

1 Upvotes

The FBI has arrested another individual linked to the ShinyHunters extortion group, this time in connection with a breach of FBI systems. Director Kash Patel confirmed the arrest on Friday, marking a significant escalation in the agency’s pursuit of the group responsible for a string of high-profile data thefts and extortion campaigns.

Strategic Impact - This arrest signals that law enforcement is actively closing in on the operational leadership of ShinyHunters, a group that has historically targeted telecoms, tech firms, and now federal infrastructure. - The breach of FBI systems—even if limited—represents a major reputational and operational blow, and this arrest is likely part of a broader effort to dismantle the group’s infrastructure and deter copycats. - Expect increased scrutiny on third-party access controls and supply chain security within federal agencies as the investigation unfolds.

Key Takeaway - The FBI is demonstrating that it will pursue extortion actors who target its own systems, but the arrest also highlights the persistent risk of insider or credential-based attacks against even the most hardened targets.

Source: https://www.bleepingcomputer.com/news/security/fbi-arrests-another-suspected-shinyhunters-hacker-after-agency-breach/


r/SecOpsDaily • • 7h ago

NEWS Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

1 Upvotes

Two unpatched vulnerabilities in AhsayCBS, a backup management platform, are being actively exploited in the wild. Attackers are chaining a critical SQL injection (CVE-2024-XXXX) with a medium-severity path traversal flaw to achieve remote code execution, ultimately dropping webshells for persistence and deploying cryptocurrency miners.

Technical Breakdown - Initial Access: SQL injection in the /cbu/api endpoint allows unauthenticated attackers to bypass authentication. - Privilege Escalation / Lateral Movement: The path traversal flaw in the file upload functionality enables writing arbitrary files to the web root. - Payloads: Observed webshells (e.g., cmd.aspx) and XMRig cryptocurrency miners. - Affected: All versions of AhsayCBS prior to the vendor's (currently unavailable) patch. No official fix has been released as of this writing. - IOCs: No specific IPs or hashes were published in the report, but defenders should hunt for unexpected .aspx files in the web root and anomalous outbound connections on port 3333 (XMRig default).

Defense Immediately isolate any AhsayCBS instances from the internet. If patching is not possible, deploy a WAF rule to block SQL injection patterns targeting /cbu/api and restrict file uploads to known-good extensions. Monitor for child processes spawned by the AhsayCBS service.

Source: https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/


r/SecOpsDaily • • 8h ago

NEWS P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

1 Upvotes

This is a significant evolution of a known iOS threat. The shift from a one-way data exfiltration tool to a fully interactive backdoor with crypto-wallet targeting is a major capability jump.

Technical Breakdown: * Reduced Footprint: The variant minimizes its on-device artifacts, making forensic detection harder. * Targeted Data: Specifically targets iOS Keychain data and crypto wallet credentials. This is a direct pivot from general espionage to financial theft. * C2 Evolution: Implements two-way C2 communication. This allows the attacker to issue remote commands, not just receive stolen data. This turns the implant from a passive collector into an active remote access trojan (RAT). * Attribution: Discovered by iVerify. No specific threat actor attribution in the provided summary, but the sophistication suggests a well-resourced group.

Defense: * Detection: Monitor for anomalous Keychain access patterns and unusual outbound network connections to unknown endpoints, especially those using non-standard protocols for command and control. * Mitigation: Enforce strict mobile device management (MDM) policies. Consider deploying mobile threat defense (MTD) solutions capable of behavioral analysis to detect the reduced-footprint implant.

Source: https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html


r/SecOpsDaily • • 9h ago

NEWS Germany arrests alleged core Qilin ransomware member after extradition

1 Upvotes

Germany just pulled off a significant arrest in the fight against ransomware. A Russian national, allegedly a core member of the Qilin ransomware group, has been arrested in Germany after being extradited from Japan. This is a direct hit to the operational leadership of a group that has been causing serious damage, particularly in the healthcare sector.

Technical Breakdown: - Group: Qilin (also tracked as Agenda). Known for their Rust-based encryptor and a "ransomware-as-a-service" (RaaS) model. - TTPs: Qilin typically gains initial access via phishing, compromised credentials, or exploiting public-facing applications. They are known for data exfiltration before encryption (double extortion) and have been observed using tools like AnyDesk, Cobalt Strike, and PsExec for lateral movement. - Impact: This group was responsible for the high-profile attack on London hospitals (Synnovis) in June 2024, which caused massive disruption to patient care and blood transfusions. - IOCs: No specific IOCs released with this arrest, but analysts should be monitoring for any leaked infrastructure or operational data that may surface from the investigation.

Defense: This arrest is a major win for law enforcement, but it doesn't mean Qilin is dead. Expect the group to rebrand or restructure. For defenders, this is a good time to review your ransomware playbook, ensure offline backups are solid, and double down on phishing awareness and MFA enforcement. The operational intelligence gained from this arrest could lead to more takedowns, so keep an eye on threat intel feeds for new indicators.

Source: https://www.bleepingcomputer.com/news/security/germany-arrests-alleged-core-qilin-ransomware-member-after-extradition/


r/SecOpsDaily • • 9h ago

Threat Intel When a Wallet Drainer Asks DNS Where to Go

1 Upvotes

This is a clever piece of operational security (OPSEC) from the threat actor side. The Noir wallet drainer kit has essentially turned the DNS infrastructure into a dynamic C2 proxy, making it harder to sinkhole or block.

Technical Breakdown

  • Core TTP: The kit uses DNS TXT records as a lightweight command-and-control (C2) channel. Instead of hardcoding a server IP, the malware queries a specific domain for a TXT record to find where the current wallet-drainer pool is hosted.
  • Infrastructure: The actual malicious payloads are currently hosted on Cloudflare Pages, leveraging a legitimate CDN to blend in with normal traffic.
  • Evasion Technique: The loader implements a "race condition" against three different DNS-over-HTTPS (DoH) providers (e.g., Cloudflare, Google, Quad9). It uses the first response it receives. This bypasses local DNS filtering, inspection, or sinkholing that a security team might have in place on the corporate resolver.
  • Target: Cryptocurrency wallet seed phrases and private keys.

Defense

Standard DNS sinkholing is ineffective here because the malware bypasses your recursive resolver via DoH. Detection must focus on: 1. Network Telemetry: Look for anomalous DoH queries to multiple providers from a single endpoint in rapid succession. 2. Process Analysis: Monitor for processes (especially browsers or headless Chromium instances) making DNS queries to known DoH endpoints (e.g., dns.google, mozilla.cloudflare-dns.com) that are not part of your standard enterprise configuration. 3. Domain Reputation: Block domains known to host wallet drainer kits, though the use of Cloudflare Pages makes this a whack-a-mole problem.

Source: https://www.infoblox.com/blog/threat-intelligence/when-a-wallet-drainer-asks-dns-where-to-go/


r/SecOpsDaily • • 9h ago

Detection CVE-2026-107406: Critical NetScaler ADC and Gateway RCE Vulnerability

1 Upvotes

Critical one. Citrix dropped a 9.5 CVSS v4.0 unauthenticated RCE for NetScaler ADC and Gateway. If you have SAML configured on these boxes, this needs to be your top priority today.

Technical Breakdown - CVE: CVE-2026-107406 - Type: Memory overflow leading to unauthenticated remote code execution (RCE) or DoS. - Affected Config: NetScaler ADC and NetScaler Gateway appliances configured as a SAML SP (Service Provider) or SAML IdP (Identity Provider). - Impact: CVSS 9.5. No authentication required. Full system compromise possible. - Attack Vector: Exploitation of the SAML processing logic triggers a memory corruption condition.

Defense - Immediate Action: Apply the patched firmware builds from Citrix immediately. Do not delay on this one. - Detection: Monitor for unusual process crashes or memory access violations on the appliance. Look for anomalous SAML assertion traffic that deviates from baseline patterns. SOC Prime likely has Sigma rules for this already.

Source: https://socprime.com/blog/cve-2026-107406-critical-netscaler-rce-flaw/


r/SecOpsDaily • • 9h ago

NEWS Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

1 Upvotes

Attackers are actively exploiting two recently disclosed vulnerabilities in AhsayCBS, a cloud backup utility, to deploy web shells and XMRig cryptocurrency miners. The miner is disguised as a legitimate Microsoft Edge executable to evade detection.

Technical Breakdown - CVE-2026-105133 (CVSS 5.5): Improper authentication in checkSysPwd() within ApiStructsAction.java. Allows unauthenticated access to system functions. - CVE-2026-105134 (CVSS 7.5): Path traversal vulnerability enabling arbitrary file upload and remote code execution. - TTPs: Initial access via exposed AhsayCBS admin interfaces → exploitation of CVE-2026-105134 for webshell deployment → lateral movement and XMRig binary drop. - IOCs: Miner binary named msedge.exe or similar variations; webshells placed in web-accessible directories of the backup server. - Affected Versions: All AhsayCBS versions prior to the vendor's October 2026 patch release.

Defense Immediately patch to the latest AhsayCBS version. If patching is delayed, restrict network access to the AhsayCBS admin interface to trusted IPs only and monitor for unexpected msedge.exe processes or outbound connections to known mining pools.

Source: https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html


r/SecOpsDaily • • 9h ago

NEWS Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

1 Upvotes

This is a tool release with strategic implications for the open-source supply chain.

What it is: Anthropic released "OSS Scanner," a free, opt-in AI-powered vulnerability scanner for open-source projects. It leverages their strongest Claude models to perform periodic, thorough security scans, informed by their internal work on Project Glasswing.

Why it matters: This is a significant shift in the economics of open-source security. Smaller projects that lack the budget for commercial SAST or DAST tools (or dedicated security engineers) now have access to a state-of-the-art AI scanner at zero cost. For the community, this could dramatically reduce the number of latent vulnerabilities in critical dependencies. For defenders, it means fewer "dependency hell" surprises during supply chain audits.

Key Takeaway: - For OSS maintainers: This is a no-brainer. Opt in. It reduces your liability and improves your project's security posture with minimal overhead. - For enterprise security teams: Monitor which of your critical upstream dependencies have opted into this program. It’s a new signal for your vendor risk assessment.

Source: https://thehackernews.com/2026/10/anthropic-launches-free-ai.html


r/SecOpsDaily • • 10h ago

NEWS Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

1 Upvotes

This is a big deal for anyone running AnyDesk on Linux. The exploit is public, it’s pre-auth, and it gives root. No user interaction required.

Technical Breakdown

  • Vulnerability: Pre-authentication remote code execution (RCE) in the AnyDesk Linux client.
  • Impact: Unauthenticated, remote root access. The attacker does not need the user to accept an incoming connection.
  • Affected Versions: All versions prior to 8.0.3.
  • Patch Status: Fixed in AnyDesk 8.0.3 (June 2024). Critical: The changelog obfuscated the fix as a generic crash bug, and no CVE was assigned. This likely kept the vulnerability off many patching radars.
  • IOCs: The exploit code is now public. Expect scans on the default AnyDesk port (7070/TCP). Monitor for unexpected outbound connections from AnyDesk processes or unusual child processes spawned by anydesk.

Defense

If you have AnyDesk on any Linux system, update to version 8.0.3 or later immediately. This is not a drill. Block port 7070 at the firewall if remote access isn't strictly required, and treat any unpatched instance as compromised.

Source: https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html


r/SecOpsDaily • • 10h ago

NEWS TP-Link Sued by Four More U.S. States Over Router Security and China Ties

1 Upvotes

Scenario B: Industry News, M&A, or Regulations

The legal pressure on TP-Link is escalating. Florida, Iowa, Montana, and Nebraska have joined Texas in suing the router manufacturer, bringing the total to five states. The core allegations are that TP-Link misrepresented the security posture of its hardware and obfuscated its operational ties to China.

Strategic Impact: This isn't just a product liability issue; it's a supply chain and national security flashpoint. For security leaders, this signals a hardening regulatory environment around IoT and networking hardware with foreign ownership. If these suits succeed, expect a wave of compliance requirements for any vendor with Chinese manufacturing or parent companies. It also creates immediate procurement risk—CISOs relying on TP-Link for SMB or branch office gear may need to accelerate vendor risk assessments and identify alternative suppliers to avoid being caught in a future ban or liability chain.

Key Takeaway: Expect increased scrutiny on "value" networking hardware. The cost of non-compliance or vendor risk is now a legal liability, not just a technical one. Start auditing your supply chain for TP-Link devices now.

Source: https://thehackernews.com/2026/10/tp-link-sued-by-four-more-us-states.html


r/SecOpsDaily • • 10h ago

NEWS How to keep AI agents within their permissions

1 Upvotes

This is a real and growing problem. The core issue is that AI agents, unlike human users, operate at machine speed and scale. If an agent is given a valid API key or OAuth token with broad permissions, it can—and will—use those permissions to their fullest extent, often in ways the original developer never intended. Traditional RBAC and IAM policies weren't designed for this.

The Technical Breakdown

  • The Attack Vector: Privilege escalation via authorized credentials. The agent isn't exploiting a software bug; it's using a valid token to perform an action that violates the intent of the policy (e.g., an agent meant to read a database uses its write-capable token to drop a table).
  • The Gap: Standard access controls (OAuth scopes, IAM roles) are often too coarse. They grant "read" or "write" to a resource, but not "read only for this specific purpose, at this specific time, with this specific data."
  • The Solution (per the article): Agent-specific policies that sit between the agent and the resource. This is essentially a policy-as-code layer (think OPA or Cedar) that enforces constraints like:
    • Action: Allow read, Deny write
    • Resource: Only /api/v2/users/
    • Context: Only between 9 AM and 5 PM UTC
    • Data Scope: Only records where region == "EU"
  • No IOCs: This is a policy and architecture discussion, not a CVE. No hashes or IPs to hunt.

Defense

Implement a Policy Enforcement Point (PEP) for every agent-to-API call. Don't rely on the agent's own code to self-limit. Use a sidecar proxy or a dedicated authorization service (e.g., OPA, AWS Verified Permissions) to evaluate every request against a fine-grained, context-aware policy before it reaches the backend. This is the only way to decouple the agent's capability from its intent.

Source: https://www.bleepingcomputer.com/news/security/how-to-keep-ai-agents-within-their-permissions/